{"schema_version":"1.7.3","id":"GHSA-wp3j-rvfp-624h","published":"2022-05-14T01:08:49Z","modified":"2024-11-30T05:39:08.392749Z","aliases":["CVE-2015-3900"],"summary":"RubyGems vulnerable to DNS hijack attack","details":"RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a \"DNS hijack attack.\"","affected":[{"package":{"name":"rubygems-update","ecosystem":"RubyGems","purl":"pkg:gem/rubygems-update"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.16"}]}],"versions":["2.0.0","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.15","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wp3j-rvfp-624h/GHSA-wp3j-rvfp-624h.json"}},{"package":{"name":"rubygems-update","ecosystem":"RubyGems","purl":"pkg:gem/rubygems-update"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.4"}]}],"versions":["2.2.0","2.2.1","2.2.2","2.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wp3j-rvfp-624h/GHSA-wp3j-rvfp-624h.json"}},{"package":{"name":"rubygems-update","ecosystem":"RubyGems","purl":"pkg:gem/rubygems-update"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4.0"},{"fixed":"2.4.7"}]}],"versions":["2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wp3j-rvfp-624h/GHSA-wp3j-rvfp-624h.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3900"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubygems-update/CVE-2015-3900.yml"},{"type":"WEB","url":"https://puppet.com/security/cve/CVE-2015-3900"},{"type":"WEB","url":"https://web.archive.org/web/20170331091241/https://puppet.com/security/cve/CVE-2015-3900"},{"type":"WEB","url":"https://web.archive.org/web/20200228055155/http://www.securityfocus.com/bid/75482"},{"type":"WEB","url":"https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-007/?fid=6356"},{"type":"WEB","url":"https://www.trustwave.com/Resources/SpiderLabs-Blog/Attacking-Ruby-Gem-Security-with-CVE-2015-3900"},{"type":"WEB","url":"http://blog.rubygems.org/2015/05/14/CVE-2015-3900.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163502.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163600.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-August/164236.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1657.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/06/26/2"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html"}],"database_specific":{"cwe_ids":["CWE-350"],"github_reviewed":true,"github_reviewed_at":"2023-03-10T02:29:09Z","nvd_published_at":"2015-06-24T14:59:00Z","severity":"HIGH"}}